The new generation of ultra-cheap smart glasses is shockingly hackable - ABC News & Headlines – Australian Broadcasting Corporation
An ABC investigation has uncovered security flaws in AI smart glasses sold in Australia. (ABC News: Kylie Silvester)
The new generation of ultra-cheap smart glasses leaves Australians' personal data, images and videos exposed to hackers, due to security flaws.
Independent testing conducted for the ABC shows the devices can be accessed by a nearby attacker without a password, using only Bluetooth.
At least one supplier has made the decision to wind down its supply, because of the furore surrounding the devices.
The new generation of ultra-cheap smart glasses is exposing Australians' sensitive data, images and videos to hackers, an investigation by ABC News has found.
Independent testing by cyber security experts has revealed a suite of serious vulnerabilities, and found an attacker can gain control of the glasses and any stored images using only Bluetooth.
"Another person with the same app can log into the glasses without a password, [because] there is no password," said David Crees, the lead researcher on testing conducted for the ABC by NSB Cyber and Abstract Shield.
David Crees says someone can gain control of a stranger's smart glasses using only Bluetooth. (ABC News: Scott Preston)
"It shouldn't be possible — it is not possible in pretty much every other proper consumer electronic," he said.
The ability to hijack a stranger's glasses with Bluetooth alone was one of more than a dozen flaws he found in six days of testing the AI-enabled smart glasses, the phone app, and its website.
The findings have also horrified legal experts, who said the security flaws were so serious the product likely breached the Privacy Act, Australian consumer law, and the government's new Cyber Security Act.
"It's really disturbing to read the extent of the failure to take even basic steps to protect personal data," said Kimberlee Weatherall from the University of Sydney, a tech regulation specialist.
"They don't seem to have encrypted it, they don't seem to have put passwords on it, they don't seem to have put even basic protections on the information that's on the website.
"It's a really clear breach [of the Privacy Act]."
Kimberlee Weatherall says the security flaws are in breach of Australian law. (ABC News: Billy Cooper)
There has been growing public backlash to the recent influx of cheap smart glasses to Australia, with calls for an import ban over privacy concerns about their ability to record in secret.
The devices, which look like ordinary glasses, let the wearer capture images, video and audio with the press of a button, and have attracted the nickname "pervert glasses" because it is not always clear when they are in use.
Now, revelations about their security flaws raise a parallel set of privacy concerns for the glasses' owners.
The testing conducted for ABC News assessed two pairs of glasses — one costing $60 from the online retailer Temu, and another costing $110, bought from a Sydney-based importer called BDI Technology via Big W Marketplace.
Similar versions in a comparable price range have also been available in recent months from Dick Smith, Kmart, and Amazon, and all appear to rely on the same mobile phone app, called HeyCyan.
Like many ethical hackers, Mr Crees first honed his skills as a cyber criminal, but now runs his own company called Abstract Shield, which is often hired by companies to detect security flaws before an attacker can.
"I'll spend anywhere from a week to a month going through a bit of software or a server or a website and finding everything that's wrong with it."
David Crees found security flaws on two pairs of cheaper smart glasses he tested. (ABC News: Chris Taylor)
But he said it was clear straight away there was "no chance" these glasses were tested to a basic minimum standard before they hit Australian shelves.
"If you think about AirPods or Samsung earbuds, you have to hold a button on the device for [several] seconds, and then you can pair it with a new phone," Mr Crees said.
"That protects the device, [but] this has nothing."
Professor Weatherall said the glasses also violated Australia's privacy laws and were likely to breach several sections of the yet-to-be-used Cyber Security Act, which came into effect in March.
"The rules say that the password must be unique," she said.
"It doesn't even seem like they were applying a password, which might mean that their standards are so low they don't even technically breach that rule, which I find amazing."
Aside from the hacking risk, the testing also found Australian user data was being sent to China in many instances.
It revealed anything spoken or typed to the in-built AI companion, along with any images submitted to AI, was sent first to a server in Shenzhen.
Depending on the function being performed, the data might then be passed to another Chinese server belonging to a different company, or to the US, although users are not explicitly told.
"The [Privacy] Act says if it's practical, you have to identify the country," Professor Weatherall said.
"It's not at all clear to me why they couldn't have put China into the privacy policy," she said, noting that the document only makes specific mention of Singapore.
The AI companion embedded in the glasses sometimes returned inaccurate answers or error messages when asked about topics the Chinese government considers sensitive.
In one instance, when asked about China's well-documented persecution of millions of Uyghur Muslims in Xinjiang province, the chatbot said there was "no credible evidence".
It declined to discuss the Tiananmen Square massacre and proposed "more positive topics" instead.
These findings, along with server locations, led researchers to conclude the chatbot companion relied at least in part on Chinese sovereign AI models.
"There is a high degree of uncertainty when it comes to where the data is going," said Evan Vougdis, from NSB Cyber, who oversaw the research.
"Is it being used for further training [of Chinese AI models]? Is it being used for surveillance?"
Evan Vougdis says people buying smart glasses should be aware of potential risks. (ABC News: Chris Taylor)
The testing did not definitively determine how the data was being used, but Mr Vougdis said any Australians considering buying the product should be aware of the risk they were taking.
The developer of the HeyCyan app is Shenzhen Qingcheng Future Technology Co., based in mainland China.
The ABC made repeated attempts to contact the company about its security flaws and seek a response, but received no reply.
It appeared HeyCyan's developers had attempted to patch some security flaws after the ABC shared the findings, but most vulnerabilities remained unaddressed.
David Crees says there was "no chance" the smart glasses were tested to a basic minimum standard. (ABC News: Chris Taylor)
Mr Crees said the flaws were so many and substantial that a total fix was impossible.
"You'd have to update 300 different brands of glasses and the app and the website … it'd take like a year to fix this. The only real solution that I see is a recall," he said.
The ABC understands at least one Australian retailer paused its supply because of the furore surrounding the devices.
BDI Technology, which is also listed as the supplier to Dick Smith and on Big W's Marketplace platform, said it was no longer selling smart glasses.
Carly Kind says there has been extreme community backlash to smart glasses. (ABC News: Mark Rigby)
"I'm not surprised," Privacy Commissioner Carly Kind said.
"There has been a really extreme backlash to these technologies. Many of these companies really prize their reputation in the Australian community, and I think they [would] do well to listen to that community concern."
The ABC did not receive on-the-record responses from any other retailers.
